Suspected cloud account or session compromise involving finance-admin. Token reuse across reported geographies, an unmanaged device, and role assumption without MFA warrant prompt containment. The telemetry does not establish token theft, unauthorized access, or data exfiltration.
09:41:03 auth.success user=finance-admin source=185.220.101.4 geo=NL device=unmanaged 09:41:06 oauth.token_reuse session=8fa2 previous_geo=US interval=164s 09:41:09 cloud.role_assume role=BillingAdmin mfa=not_present 09:41:12 storage.list bucket=customer-exports count=147
First action: Preserve authentication, token, role-assumption, and storage audit records; correlate principal and session identifiers before broad containment.
